Access control
Identity, roles, and least-privilege boundaries decide who can reach patient information — enforced in the backend, not only hidden in the interface.
SERVICES / HEALTHCARE SOFTWARE
I build healthcare software as both a podiatric medical student and a cybersecurity engineer — treating patient-data protection as part of the architecture rather than a checklist added at the end.
01 / SAFEGUARDS IN THE ARCHITECTURE
HIPAA’s security safeguards describe outcomes — control access, protect information, and stay accountable for it. These are the engineering practices I use to support those outcomes in real software.
Identity, roles, and least-privilege boundaries decide who can reach patient information — enforced in the backend, not only hidden in the interface.
Health information is encrypted in transit and at rest, with data minimization so a system only stores what it genuinely needs to do its job.
Meaningful logging of access and changes, so a practice can answer who saw what, when, and why — without logging the sensitive values themselves.
Threat modeling, input validation, dependency review, and testing how the system might fail before it is trusted with real patient data.
02 / HEALTHCARE WORK
FootCheckAI & FOOT HEALTH
Bringing technology closer to foot health. A platform focused on early awareness, self-monitoring, and education.
BodyOSPERSONAL HEALTH
An AI-assisted fitness platform connecting training, progress tracking, and a personal coaching experience.
FOUNDER · HEALTHCARE TECHNOLOGY
My healthcare technology studio, connecting product design and engineering to the needs of clinicians and patients.
GoogolgonHEALTHCARE PORTFOLIO
A healthcare portfolio platform with a cohesive brand system, marketing site, and structured content.
03 / HOW THE WORK RUNS
Each stage keeps engineering decisions and data-protection decisions in the same conversation.
Identify what health information the system touches, where it travels, and who genuinely needs it.
Define identity, roles, storage, encryption, and the trust boundaries between services.
Implement the product with validation, authorization, and audit logging as part of the feature, not an afterthought.
Test how the system could fail, review dependencies and access paths, and document what remains for your compliance team.
Engineering practices support compliance; they do not replace a formal HIPAA risk assessment, legal review, or a business associate agreement. I work alongside those.
GOOD WORK STARTS WITH A CONVERSATION